On April 6, 2023, the U.S. Department of the Treasury published its first illicit-finance risk assessment devoted to decentralized finance. Its central regulatory conclusion was sharper than a general warning about crypto crime: a service engaged in activity covered by the Bank Secrecy Act could already have anti-money-laundering and countering-the-financing-of-terrorism obligations, regardless of whether it called itself decentralized or planned to become decentralized.

That mattered because Treasury treated “DeFi” as an imperfect industry label, not a legal safe harbor. At the same time, the assessment did not create a rule, announce an enforcement case or settle which people behind every protocol qualified as a regulated financial institution. The document expressly said it did not alter existing legal obligations, issue new regulatory interpretations or establish new supervisory expectations.

Treasury separated branding from control

Treasury said there was no generally accepted definition of DeFi. For the assessment, the term broadly covered virtual-asset protocols and services that purported to enable automated peer-to-peer transactions, often through blockchain-based smart contracts. It also warned that some projects retained a controlling organization, concentrated governance rights or administrative keys, making the degree of decentralization a facts-and-circumstances question.

The report’s scope was not unlimited. Direct transfers between two unhosted wallets, when they involved neither smart contracts nor facilitation by a virtual-asset service provider, fell outside its working definition of DeFi services. That boundary was specific to the assessment and was not presented as a permanent legal classification.

Treasury identified ransomware operators, thieves, scammers and cyber actors associated with the Democratic People’s Republic of Korea among the illicit users of DeFi services. It described noncompliance by services already subject to AML/CFT and sanctions duties as the primary vulnerability. It also identified possible gaps where a service fell outside the Bank Secrecy Act’s definition of a financial institution, uneven implementation of international standards, and cybersecurity weaknesses that enabled theft and fraud.

The report was narrower than the headline risk

The assessment included important qualifications. Treasury said illicit activity was only a subset of overall DeFi activity, that DeFi remained a minor part of the virtual-asset ecosystem, and that most money laundering, terrorist financing and proliferation financing by volume and value occurred in fiat currency or other traditional assets. Those statements did not negate the documented DeFi risks; they limited claims about scale.

The international context supported Treasury’s concern about inconsistent implementation. In its June 2022 targeted update, the Financial Action Task Force reported that 29 of 98 jurisdictions responding to its March 2022 survey had passed legislation implementing the Travel Rule, with only a small subset beginning enforcement. FATF also said it would keep monitoring DeFi-related risks. That survey measured adoption of Travel Rule laws across responding jurisdictions, not the share of illicit activity occurring through DeFi.

What changed on April 6

The immediate change was policy framing, not statutory text. Treasury recommended stronger supervision and enforcement for covered virtual-asset activity, more industry outreach and possible additional guidance. It also proposed evaluating whether gaps in the Bank Secrecy Act allowed some DeFi services to remain outside the financial-institution definition, while continuing work with foreign partners and encouraging stronger code testing, threat sharing and compliance tools.

Treasury asked for public input on factors that should determine whether a DeFi service is a financial institution and how obligations should vary with services offered. Those questions showed that major perimeter issues remained open on April 6, 2023.

For protocol developers and governance participants, the institutional signal was significant: claims of decentralization would be tested against actual functions and control. For policymakers, the report supplied a federal risk framework and a menu of possible next steps. But it was still an assessment. Any later guidance, rulemaking, legislation or court decision required its own record and could not be treated as having taken effect on April 6.

Primary sourceU.S. Treasury — Illicit Finance Risk Assessment of Decentralized Finance

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.